Guard work item detail queries against the anonymous complexity cap

What does this MR do and why?

all_queries_spec.rb asserts the work item detail queries stay under the authenticated (250) and admin (300) complexity caps, but never under the unauthenticated one (200), which is the limit the widget-splitting work was done to get below. This adds that assertion for the two documents an anonymous visitor can actually send.

Measured with __typename injected, as Apollo sends it, and useWorkItemFeatures: true:

Document Complexity Cap
work_item_by_iid.query.graphql 200 200
work_item_by_id.query.graphql 198 200

Mutations and subscriptions need a session, so they're deliberately left out of the new block.

References

How to set up and validate locally

  1. Run the new examples:

    bundle exec rspec ee/spec/graphql/all_queries_spec.rb -e "work item detail query complexity for unauthenticated users"
  2. Re-add contacts { nodes { id email } } under crmContacts in app/assets/javascripts/work_items/graphql/base_work_item_features.fragment.graphql and confirm both examples now fail, at 204 and 202.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Merge request reports

Loading
Loading